CVE-2021-3672
Description
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.
Risk Information
Base Score
5.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
Exploitation Probability
0.055
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| library for asynchronous name resolution (USN-5034-1) libc-ares2_1.14.0-1ubuntu0.1_i386.deb | Linux |
| library for asynchronous name resolution (USN-5034-1) libc-ares2_1.14.0-1ubuntu0.1_amd64.deb | Linux |
| library for asynchronous name resolution (USN-5034-1) libc-ares2_1.15.0-1ubuntu0.1_i386.deb | Linux |
| library for asynchronous name resolution (USN-5034-1) libc-ares2_1.15.0-1ubuntu0.1_amd64.deb | Linux |
| library for asynchronous name resolution (USN-5034-1) libc-ares2_1.17.1-1ubuntu0.1_i386.deb | Linux |
| library for asynchronous name resolution (USN-5034-1) libc-ares2_1.17.1-1ubuntu0.1_amd64.deb | Linux |
| SUSE-SU-2021:2690-1(SUSE Linux Enterprise Server 12-SP5 ) libcares2-1.9.1-9.7.1.x86_64.rpm | Linux |
| SUSE-SU-2021:2690-1(SUSE Linux Enterprise Server 12-SP5 ) libcares2-debuginfo-1.9.1-9.7.1.x86_64.rpm | Linux |
| SUSE-SU-2021:2690-1(SUSE Linux Enterprise Server 12-SP5 ) libcares2-debugsource-1.9.1-9.7.1.x86_64.rpm | Linux |
| (RHSA-2021:3623) nodejs:12 security and bug fix update nodejs-12.22.5-1.module+el8.4.0+12242+af52a4c7.x86_64.rpm | Linux |
| (RHSA-2021:3623) nodejs:12 security and bug fix update nodejs-debugsource-12.22.5-1.module+el8.4.0+12242+af52a4c7.x86_64.rpm | Linux |
| (RHSA-2021:3623) nodejs:12 security and bug fix update nodejs-devel-12.22.5-1.module+el8.4.0+12242+af52a4c7.x86_64.rpm | Linux |
| (RHSA-2021:3623) nodejs:12 security and bug fix update nodejs-docs-12.22.5-1.module+el8.4.0+12242+af52a4c7.noarch.rpm | Linux |
| (RHSA-2021:3623) nodejs:12 security and bug fix update nodejs-full-i18n-12.22.5-1.module+el8.4.0+12242+af52a4c7.x86_64.rpm | Linux |
| (RHSA-2021:3623) nodejs:12 security and bug fix update npm-6.14.14-1.12.22.5.1.module+el8.4.0+12242+af52a4c7.x86_64.rpm | Linux |
| Nodejs update (ELSA-2021-3623) nodejs-12.22.5-1.module+el8.4.0+20308+065a70e3.x86_64.rpm | Linux |
| Nodejs-devel update (ELSA-2021-3623) nodejs-devel-12.22.5-1.module+el8.4.0+20308+065a70e3.x86_64.rpm | Linux |
| Nodejs-docs update (ELSA-2021-3623) nodejs-docs-12.22.5-1.module+el8.4.0+20308+065a70e3.noarch.rpm | Linux |
| Nodejs-full-i18n update (ELSA-2021-3623) nodejs-full-i18n-12.22.5-1.module+el8.4.0+20308+065a70e3.x86_64.rpm | Linux |
| Nodejs-nodemon update (ELSA-2021-3623) nodejs-nodemon-2.0.3-1.module+el8.4.0+20281+eb64e322.noarch.rpm | Linux |
| Nodejs-packaging update (ELSA-2021-3623) nodejs-packaging-17-3.module+el8.1.0+5393+aaf413e3.noarch.rpm | Linux |
| Npm update (ELSA-2021-3623) npm-6.14.14-1.12.22.5.1.module+el8.4.0+20308+065a70e3.x86_64.rpm | Linux |
| (RHSA-2021:3666) nodejs:14 security and bug fix update nodejs-14.17.5-1.module+el8.4.0+12247+e2879e58.x86_64.rpm | Linux |
| (RHSA-2021:3666) nodejs:14 security and bug fix update nodejs-debugsource-14.17.5-1.module+el8.4.0+12247+e2879e58.x86_64.rpm | Linux |
| (RHSA-2021:3666) nodejs:14 security and bug fix update nodejs-devel-14.17.5-1.module+el8.4.0+12247+e2879e58.x86_64.rpm | Linux |
| (RHSA-2021:3666) nodejs:14 security and bug fix update nodejs-docs-14.17.5-1.module+el8.4.0+12247+e2879e58.noarch.rpm | Linux |
| (RHSA-2021:3666) nodejs:14 security and bug fix update nodejs-full-i18n-14.17.5-1.module+el8.4.0+12247+e2879e58.x86_64.rpm | Linux |
| (RHSA-2021:3666) nodejs:14 security and bug fix update npm-6.14.14-1.14.17.5.1.module+el8.4.0+12247+e2879e58.x86_64.rpm | Linux |
| Nodejs update (ELSA-2021-3666) nodejs-14.17.5-1.module+el8.4.0+20313+f90c2973.x86_64.rpm | Linux |
| Nodejs-devel update (ELSA-2021-3666) nodejs-devel-14.17.5-1.module+el8.4.0+20313+f90c2973.x86_64.rpm | Linux |
| Nodejs-docs update (ELSA-2021-3666) nodejs-docs-14.17.5-1.module+el8.4.0+20313+f90c2973.noarch.rpm | Linux |
| Nodejs-full-i18n update (ELSA-2021-3666) nodejs-full-i18n-14.17.5-1.module+el8.4.0+20313+f90c2973.x86_64.rpm | Linux |
| Nodejs-nodemon update (ELSA-2021-3666) nodejs-nodemon-2.0.3-1.module+el8.3.0+7818+6cd30d85.noarch.rpm | Linux |
| Nodejs-packaging update (ELSA-2021-3666) nodejs-packaging-23-3.module+el8.3.0+7818+6cd30d85.noarch.rpm | Linux |
| Npm update (ELSA-2021-3666) npm-6.14.14-1.14.17.5.1.module+el8.4.0+20313+f90c2973.x86_64.rpm | Linux |
| (RHSA-2022:2043) c-ares security update c-ares-debugsource-1.13.0-6.el8.i686.rpm | Linux |
| (RHSA-2022:2043) c-ares security update c-ares-debugsource-1.13.0-6.el8.x86_64.rpm | Linux |
| nodejs:12 security and bug fix update (RLSA-2021:3623) npm-6.14.14-1.12.22.5.1.module+el8.4.0+647+e905fa21.x86_64.rpm | Linux |
| nodejs:12 security and bug fix update (RLSA-2021:3623) c-ares-1.13.0-6.el8.i686.rpm | Linux |
| nodejs:12 security and bug fix update (RLSA-2021:3623) c-ares-1.13.0-6.el8.x86_64.rpm | Linux |
| nodejs:12 security and bug fix update (RLSA-2021:3623) nodejs-12.22.5-1.module+el8.4.0+647+e905fa21.x86_64.rpm | Linux |
| nodejs:12 security and bug fix update (RLSA-2021:3623) nodejs-docs-12.22.5-1.module+el8.4.0+647+e905fa21.noarch.rpm | Linux |
| nodejs:12 security and bug fix update (RLSA-2021:3623) c-ares-devel-1.13.0-6.el8.i686.rpm | Linux |
| nodejs:12 security and bug fix update (RLSA-2021:3623) c-ares-devel-1.13.0-6.el8.x86_64.rpm | Linux |
| nodejs:12 security and bug fix update (RLSA-2021:3623) nodejs-devel-12.22.5-1.module+el8.4.0+647+e905fa21.x86_64.rpm | Linux |
| nodejs:12 security and bug fix update (RLSA-2021:3623) nodejs-full-i18n-12.22.5-1.module+el8.4.0+647+e905fa21.x86_64.rpm | Linux |
| nodejs:12 security and bug fix update (RLSA-2021:3623) nodejs-packaging-23-3.module+el8.5.0+733+de4fee6c.noarch.rpm | Linux |
| (RHSA-2021:3623)Important: security and bug fix update nodejs-debuginfo-12.22.5-1.module+el8.4.0+12242+af52a4c7.x86_64.rpm | Linux |
| (RHSA-2021:3623)Important: security and bug fix update nodejs-nodemon-2.0.3-1.module+el8.4.0+11732+c668cc9f.noarch.rpm | Linux |
| (RHSA-2021:3623)Important: security and bug fix update nodejs-packaging-17-3.module+el8.1.0+3369+37ae6a45.noarch.rpm | Linux |
| SUSE-SU-2021:2760-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) libcares2-1.17.1+20200724-3.14.1.x86_64.rpm | Linux |
| SUSE-SU-2021:2760-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) c-ares-devel-1.17.1+20200724-3.14.1.x86_64.rpm | Linux |
| SUSE-SU-2021:2760-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) c-ares-debugsource-1.17.1+20200724-3.14.1.x86_64.rpm | Linux |
| SUSE-SU-2021:2760-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) libcares2-debuginfo-1.17.1+20200724-3.14.1.x86_64.rpm | Linux |
| Important: nodejs:12 security and bug fix update nodejs-packaging-17-3.module_el8.3.0+2023+d2377ea3.noarch.rpm | Linux |
| Important: nodejs:12 security and bug fix update nodejs-packaging-17-3.module_el8.4.0+2521+c668cc9f.noarch.rpm | Linux |
| Important: nodejs:14 security and bug fix update nodejs-nodemon-2.0.3-1.module_el8.4.0+2521+c668cc9f.noarch.rpm | Linux |
| nodejs:12 security and bug fix update (RLSA-2021:3623) nodejs-nodemon-2.0.3-1.module+el8.6.0+982+9fdca2d4.noarch.rpm | Linux |
| nodejs:14 security and bug fix update (RLSA-2021:3666) nodejs-packaging-23-3.module+el8.7.0+1071+4bdda2a8.noarch.rpm | Linux |
| nodejs:14 security and bug fix update (RLSA-2021:3666) nodejs-nodemon-2.0.3-1.module+el8.6.0+982+9fdca2d4.noarch.rpm | Linux |
| Npm update (ELSA-2025-8514) npm-10.8.2-1.20.19.2.1.module+el8.10.0+90611+29f3ae1e.x86_64.rpm | Linux |
| Nodejs-packaging-bundler update (ELSA-2025-8514) nodejs-packaging-bundler-2021.06-4.module+el8.10.0+90611+29f3ae1e.noarch.rpm | Linux |
| Nodejs-packaging update (ELSA-2025-8514) nodejs-packaging-2021.06-4.module+el8.10.0+90611+29f3ae1e.noarch.rpm | Linux |
| Nodejs-nodemon update (ELSA-2025-8514) nodejs-nodemon-3.0.1-1.module+el8.10.0+90611+29f3ae1e.noarch.rpm | Linux |
| Nodejs-full-i18n update (ELSA-2025-8514) nodejs-full-i18n-20.19.2-1.module+el8.10.0+90611+29f3ae1e.x86_64.rpm | Linux |
| Nodejs-docs update (ELSA-2025-8514) nodejs-docs-20.19.2-1.module+el8.10.0+90611+29f3ae1e.noarch.rpm | Linux |
| Nodejs-devel update (ELSA-2025-8514) nodejs-devel-20.19.2-1.module+el8.10.0+90611+29f3ae1e.x86_64.rpm | Linux |
| Nodejs update (ELSA-2025-8514) nodejs-20.19.2-1.module+el8.10.0+90611+29f3ae1e.x86_64.rpm | Linux |
| Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability (CVE-2021-3672) | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234